GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
21,198 advisories
Filter by severity
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
High
CVE-2020-2228
was published
for
org.jenkins-ci.plugins:gitlab-oauth
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins 'keep forever' badge icon
High
CVE-2020-2222
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
High
CVE-2020-2226
was published
for
org.jenkins-ci.plugins:matrix-auth
(Maven)
May 24, 2022
Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
High
CVE-2020-2225
was published
for
org.jenkins-ci.plugins:matrix-project
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Deployer Framework Plugin
High
CVE-2020-2227
was published
for
org.jenkins-ci.plugins:deployer-framework
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins job build time trend
High
CVE-2020-2220
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins upstream cause
High
CVE-2020-2221
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins console links
High
CVE-2020-2223
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in single axis builds tooltips in Jenkins Matrix Project Plugin
High
CVE-2020-2224
was published
for
org.jenkins-ci.plugins:matrix-project
(Maven)
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
High
CVE-2020-1147
was published
for
Microsoft.NETCore.App
(NuGet)
May 24, 2022
SilverStripe Web Cache Poisoning through HTTPRequestBuilder
Moderate
CVE-2019-19326
was published
for
silverstripe/framework
(Composer)
May 24, 2022
ke_search for Typo3 XSS Vulnerability
Moderate
CVE-2020-15517
was published
for
tpwd/ke_search
(Composer)
May 24, 2022
jh_captcha for Typo3 XSS Vulnerability
Moderate
CVE-2020-15514
was published
for
haffner/jh_captcha
(Composer)
May 24, 2022
Missing permission checks in Zephyr for JIRA Test Management Plugin
Moderate
CVE-2020-2216
was published
for
org.jenkins-ci.plugins:zephyr-for-jira-test-management
(Maven)
May 24, 2022
Password stored in plain text by Jenkins HP ALM Quality Center Plugin
Low
CVE-2020-2218
was published
for
org.jenkins-ci.plugins:hp-quality-center
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
Moderate
CVE-2020-2215
was published
for
org.jenkins-ci.plugins:zephyr-for-jira-test-management
(Maven)
May 24, 2022
Content-Security-Policy protection for user content disabled by Jenkins ZAP Pipeline Plugin
Moderate
CVE-2020-2214
was published
for
com.vrondakis.zap:zap-pipeline
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Link Column Plugin
Moderate
CVE-2020-2219
was published
for
org.jenkins-ci.plugins:link-column
(Maven)
May 24, 2022
Reflected XSS in Jenkins Compatibility Action Storage Plugin
Moderate
CVE-2020-2217
was published
for
org.jenkins-ci.plugins:compatibility-action-storage
(Maven)
May 24, 2022
Credentials stored in plain text by Jenkins White Source Plugin
Moderate
CVE-2020-2213
was published
for
org.jenkins-ci.plugins:whitesource
(Maven)
May 24, 2022
Secret stored in plain text by Jenkins GitHub Coverage Reporter Plugin
Moderate
CVE-2020-2212
was published
for
io.jenkins.plugins:github-coverage-reporter
(Maven)
May 24, 2022
Reflected XSS vulnerability in Jenkins VncRecorder Plugin
Moderate
CVE-2020-2206
was published
for
org.jenkins-ci.plugins:vncrecorder
(Maven)
May 24, 2022
Secret stored in plain text by Jenkins Slack Upload Plugin
Moderate
CVE-2020-2208
was published
for
org.jenkins-ci.plugins:slack-uploader
(Maven)
May 24, 2022
Password stored in plain text by Jenkins TestComplete support Plugin
Moderate
CVE-2020-2209
was published
for
org.jenkins-ci.plugins:TestComplete
(Maven)
May 24, 2022
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
High
CVE-2020-2211
was published
for
com.elasticbox.jenkins-ci.plugins:kubernetes-ci
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API